Melba Lopez

Melba Lopez Email and Phone Number

STSM - SW Supply Chain Security @ IBM
Austin, TX, US
Melba Lopez's Location
Austin, Texas, United States, United States
Melba Lopez's Contact Details
About Melba Lopez

Melba Lopez is a seasoned cybersecurity professional currently serving as a Senior Technical Staff Member (STSM) at the IBM Office of CISO. With a primary focus on the strategy and delivery of enterprise software supply chain security, Melba plays a pivotal role in safeguarding critical assets against emerging supply chain threats. In addition to her role at IBM, Melba is deeply involved in industry initiatives aimed at fortifying software supply chains. She serves as an OWASP Dependency Track maintainer, demonstrating her commitment to advancing open-source security solutions. Previously, she held leadership positions within the Open Source Security Foundation (OpenSSF), including co-lead of the Supply Chain Integrity Working Group and Lead of the Positioning Special Interest Group. Melba’s expertise spans over 18 years, covering a diverse range of domains such as application development, cloud computing, networking, and security. Her multidisciplinary background equips her with a comprehensive understanding of the intricate landscape of cybersecurity challenges. With a Master’s degree in Cybersecurity & Information Assurance, Melba is passionate about leveraging her knowledge and experience to drive impactful changes in the cybersecurity ecosystem.

Melba Lopez's Current Company Details
IBM

Ibm

View
STSM - SW Supply Chain Security
Austin, TX, US
Website:
ibm.com
Employees:
332208
Melba Lopez Work Experience Details
  • Ibm
    Stsm - Sw Supply Chain Security
    Ibm
    Austin, Tx, Us
  • Ibm
    Sw Supply Chain Security Architect, Stsm
    Ibm Aug 2021 - Present
    Armonk, New York, Ny, Us
    • Responsible for the architecture and implementation of IBM’s Enterprise Software Supply Chain Security solution; working with executive, development, security, operations, product/consulting teams and business supporting stakeholders, further complying with NIST SSDF, C-SCRM, and White House Executive Order 14028• IBM Open Source Leader for Open SSF SLSA & Supply Chain Integrity WG, to create/enable a software supply chain security framework with various industry experts • Responsible for the security architecture and implementation for IBM Academy of Technology Humanitarian Emergency Aide List (H.E.A.L.) Project, which assists those affected by the war in Ukraine • Formerly technical leader of the IBM CISO’s E&TS Security Review Board
  • Havana Banana Press L.L.C.
    Co-Founder
    Havana Banana Press L.L.C. May 2021 - Present
  • Vmware
    Manager - Global Vulnerability Management
    Vmware Sep 2019 - Aug 2021
    Palo Alto, Ca, Us
    • Responsible for the growth and strategic direction of VMware’s vulnerability management program in the following focus areas: risk management, vulnerability lifecycle, domain & certificate management, bug bounty, public/private SaaS compliance, FedRAMP ConMon and POA&M, Merger & Acquisitions onboarding• Lead and developed team to adopt new operational processes to increase velocity and scale with growing SaaS offerings (JIRA, Confluence, Scrum/Kanban, automation)• Established Service Level Objectives (SLO) for FedRAMP and Commercial SaaS support• Successfully lead team to 475% YoY increase for audit readiness/support for commercial SaaS offerings through automation & process efficiencies resulting in multiple SOC, ISO, and PCI certifications• Expanded public-sector SaaS responsibilities resulting in 200% YoY increase for audit readiness/support • Coordinating development of customized health dashboards for KPI and Organizational health scores based on SLO/SLA • Weekly Risk & Remediation updates to CISO
  • Vmware
    Senior Information Security Engineer
    Vmware Oct 2018 - Sep 2019
    Palo Alto, Ca, Us
    o Contributing to the strategic direction for vulnerability management and security testing capabilities at VMware.o Supporting compliance and risk management activities, recommending security controls and corrective actions to mitigate vulnerability risks.o Maintaining current knowledge and understanding of the threat landscape and emerging security threats and vulnerabilities.o Performing vulnerability assessments to identify weaknesses and countermeasures and providing timely assessment reports to key stakeholders.o Conducting attack surface reviews and recommending layered defenses to prevent exploits, detect and intercept attacks, and discover threat agents.o Performing complex security test data analysis in support of security vulnerability assessment processes, including root cause analysis.o Producing vulnerability, configuration, and coverage reporting to demonstrate assessment coverage and remediation effectiveness, designing and implementing dashboards and data visualizations for various stakeholders.o Implementing processes, capabilities, and techniques for vulnerability management and security testing.o Managing the end-to-end vulnerability life-cycle from discovery to closure.o Driving development and ongoing maintenance of vulnerability management platforms.o Monitoring vulnerability disclosure mailing lists and threat intelligence feeds to identify and triage new threats and vulnerabilities targeting VMware.o Serving as an escalation point on issues, dependencies, and risks related to vulnerability scanning and security testing.
  • Vmware
    Senior Technical Account Manager, Professional Services Organization
    Vmware Feb 2016 - Oct 2018
    Palo Alto, Ca, Us
    - Consult with customers to enable VMware production adoption through education, architectural best practices, technical guidance, and troubleshooting- Assist customers’ adherence to internal security policies and compliance requirements within the VMware portfolio through VMware RBAC, hardening guidelines, STIG requirements, PCI requirements, or NIST recommendations- Proactively provide education and guidance to customers and internal TAMs around VMware security announcements and security best practices- Testing and proctoring the Networking & Security Hands on Lab for VMworld 2018
  • Lenovo
    Senior Consultant - Professional Services
    Lenovo Oct 2014 - Jan 2016
    Morrisville, Nc, Us
    - WW Proof of Technology Leader & WW VMware vRealize/NSX Practice Leader- Provide architecture designs for Lenovo Reference Architectures as well as for customer’s business and technical requirements- Develop collateral for new service offerings and solutions- Identify, sell, and implement professional services for customers based on their future direction- Assist in cloud strategy & training for Enterprise Solution Services- Mentor new and existing employees in cloud, networking, and virtualization technologies.
  • Ibm
    Senior I/T Specialist
    Ibm Sep 2010 - Sep 2014
    Armonk, New York, Ny, Us
    Recommend and deploy virtualization and cloud solutions per customer’s business and technical requirementsIdentify and/or sell new professional services for customers based on their future directionImplement proof-of-concept solutions to enable customer feature requestsBuild long-term business relationships with various customers to ensure high level of customer satisfaction.Drive the adoption of new STG Technology and IBM Cloud Solutions by presenting at IBM technical conferences and training Business Partners worldwide. Develop documentation to enable integration, training, and support for new offerings and solutions.Mentor new and existing employees on cloud and virtualization technologies
  • Ibm
    Technical Lead For Cloudburst & Esxi Solutions In Stg
    Ibm May 2009 - Sep 2010
    Armonk, New York, Ny, Us
    Developed and implemented a new cloud solution offering called CloudBurst. Integration efforts also resulted in the development of a thorough CloudBurst Cookbook Integration document for CSC, Lab Services, and internal users as well as two published white papers for end customers.Provided technical direction and leadership in the development of CloudBurst offerings. Successfully lead the “CloudBurst” multi-functional and multi-organizational team to three releases of CloudBurst. Assumed additional responsibilities to fill in resource gaps including CloudBurst Solution Test Lead, Project Management of Integration/Test/Cookbook development, and Tivoli integration owner. Advised, trained, and provided ongoing technical support to lead and directly influence professional work teams outside my department or function such as, but not limited to, CSC, GTS, Tivoli, and various internal employees worldwide. Actively participated in defining and deciding upon objectives for future CloudBurst solutions. Made recommendations on design changes and improvements to redesign the CloudBurst offerings to incorporate the latest technologies that would drive efficiency and strengthen the customer user experience.Identified systems management requirements for ESXi and worked directly with VMware communicating the requirements. Lead team to successfully deliver multiple customized ESXi images and ESXi UXSPI package development. Lead testing efforts for customized ESXi image, USB certification tests, and other testing needs (such as upgrade, SOL, SNMP, etc) as they arose. Worked directly with VMware to resolve any technical issues found by development.
  • Ibm
    Staff Sw Engineer In Stg Virtualization & Cloud Solutions Development
    Ibm Sep 2008 - May 2009
    Armonk, New York, Ny, Us
    Develop virtualization and cloud solutions for various projects including, but not limited to, VMware, Xen, KVM, and Cloud Computing.Delivered multiple releases of VMware ESXi Embedded Hypervisor, Recovery, and Installable images.Provided ongoing technical guidance for VMware ESXi Embedded Solutions for Preload, Product Engineering, Manufacturing, and TSTL teams.Successfully defined, recommended, and/or implemented software alternatives and solutions to achieve a high level of efficiency and customer satisfaction for manufacturing and/or field issues as they arose. Enabled IBM Support team to handle ESXi related issues for Level 1 Support. Also provided direct technical support for ESXi customers worldwide. Implemented and proposed proof-of-concept cloud solutions to be competitive in the marketplace. Proposed these solutions to upper-line management, resulting in new solutions offerings provided by GTS.
  • Ibm
    Staff Sw Engineer In Stg System X Preload & Custom Images
    Ibm Mar 2007 - Sep 2008
    Armonk, New York, Ny, Us
    Designed, implemented, and delivered multiple releases of VMware Embedded Hypervisor preloadRedesigned the IBM preload process architecture to a more robust comprehensive solution that is 33-40% more efficient.Successfully, defined, recommended, and implemented VMware software alternatives and solutions to achieve a high level of efficiency and customer satisfaction for manufacturing and/or field issues as they arose. Lead a team to develop and deliver Reseller Option Kit (ROK) while making decisions on design changes and improvements incorporating the latest Microsoft technologies that would drive efficiency and strengthen the customer user experience.
  • Raytheon
    Software Design Engineer In Network Centric Systems
    Raytheon Jan 2006 - Feb 2007
    Arlington, Va, Us
    Execution of all aspects of software development life-cycle related to various network/communications systems. This includes software design, code implementation, debug, integration, test, support and documentation.Implementation of various projects in a high order language on UNIX and/or Windows using modern software design methodologies. This includes specific technologies such as databases, distributed architectures, real time and/or embedded software, and system security-hardening, web-based technologies, and user interfaces/portals.Designing and improving current "Close STR Process" by utilizing Raytheon's Six Sigma Process. The new process will give an approximate raw ROI of 371%, thus saving approximately $69 K a year.
  • Ibm
    Card Design Engineering Coop
    Ibm May 2004 - Dec 2004
    Armonk, New York, Ny, Us
    Designed and implemented the architecture for a non-volatile memory card (NVRAM) that is designed for an IBM SCSI RAID storage card adapter with a removable data pack card. Delivered a set of Test Vehicles used for simulating connectors, and their use, in a real time environment. This required interpretation and implementation of high-level architectural documents.Assisted in the redesign of Blue Gene/L’s Clock Card by updating the spread spectrum function. Initiated and started work on future Blue Gene cards. Aided in the setup in the Blue Gene demo rack and demo cards.Interacted with various groups including Mechanical, Signal Integrity, Physical Design teams, vendors, and Contract Manufacturers to meet imminent deadlines.Assisted a team of experienced designers in circuit design, component selection, schematics entry, documentation in addition to Lab bring-up & debug activities for various projects with Microsoft, Adaptec, and IBM Server Cards.

Melba Lopez Skills

Virtualization Cloud Computing Vmware Integration Storage Testing Solution Architecture Networking San Linux Data Center Enterprise Architecture Ibm Servers Project Management Databases Professional Services High Availability Bladecenter Systems Management Vsphere Switches Brocade Fibre Switches Network Design Blade Technology Network Architecture Hardware Deployments Security Red Hat Linux Training Delivery Cyber Security Ibm Pureflex Systems Ibm Flex Systems Vcloud Vcloud Automation Center Vmware Nsx Ibm Network Switches Ibm Systems Director Ibm Cloudburst Ibm Smartcloud Entry Cisco Networking

Melba Lopez Education Details

  • Penn State University
    Penn State University
    Cybersecurity And Information Assurance
  • Cisco Global Cybersecurity Scholarship Program (Cohort 7)
    Cisco Global Cybersecurity Scholarship Program (Cohort 7)
    Cybersecurity
  • University Of Florida
    University Of Florida
    Electrical Engineering

Frequently Asked Questions about Melba Lopez

What company does Melba Lopez work for?

Melba Lopez works for Ibm

What is Melba Lopez's role at the current company?

Melba Lopez's current role is STSM - SW Supply Chain Security.

What is Melba Lopez's email address?

Melba Lopez's email address is me****@****ibm.com

What is Melba Lopez's direct phone number?

Melba Lopez's direct phone number is +130580*****

What schools did Melba Lopez attend?

Melba Lopez attended Penn State University, Cisco Global Cybersecurity Scholarship Program (Cohort 7), University Of Florida.

What are some of Melba Lopez's interests?

Melba Lopez has interest in Environment, Education, Poverty Alleviation, Science And Technology, Disaster And Humanitarian Relief, Human Rights, Animal Welfare, Health.

What skills is Melba Lopez known for?

Melba Lopez has skills like Virtualization, Cloud Computing, Vmware, Integration, Storage, Testing, Solution Architecture, Networking, San, Linux, Data Center, Enterprise Architecture.

Who are Melba Lopez's colleagues?

Melba Lopez's colleagues are Tom Pattison, Sonam Kumawat, Sven Nordgaard, Satya S, Dayakar Ghattolu, Alvaro Valdebenito, Larissa Neves Da Ressurreição.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.